Add Vault-scoped agent kubernetes roles + agents AppRole #109

Merged
benvin merged 2 commits from benvin/agent-kube-contexts into master 2026-08-02 21:55:06 +10:00
Owner

Why

Agentic workloads currently need cluster-admin/root kubeconfig contexts to do routine per-domain work. This adds domain-scoped, Vault-issued kubernetes credentials plus an agents AppRole so agents get least-privilege access instead of escalating.

Changes

  • Add kubernetes_secret_backend_role configs agent-dhcp, agent-dns, agent-certs, agent-storage (au/syd1):
    • agent-dhcp (Role, ns dhcp-system): full verbs on kea.unkin.net CRDs; get/list/watch pods/services/configmaps/events + pods/log.
    • agent-dns (service_account_name mode): mints tokens for the static agent-dns SA (argocd-apps#332) whose per-namespace RoleBindings confine access to bind-system/bind-internal/bind-external/externaldns. allowed_kubernetes_namespaces: [bind-system] (the SA's namespace).
    • agent-certs (Role, ns cert-manager): full verbs on cert-manager.io + acme.cert-manager.io (closes the orders/challenges debugging gap); get/list/watch/delete secrets; get/list/watch pods + pods/log. Secret delete confined to cert-manager.
    • agent-storage (Role, ns cephrgw-system): full verbs on ceph.unkin.net CRDs (buckets/bucketaccesses/objectstoreusers); get/list/watch pods + pods/log.
  • Extend the kubernetes_secret_backend_role module with an optional service_account_name; when set, generated_role_rules/kubernetes_role_type are omitted (the SA's own bindings supply RBAC).
  • Add creds policies for each role, bound to the kubernetes_au_syd1_cluster_operator ldap group (human kubectl use) and the agents AppRole (programmatic use).
  • Add the agents AppRole (mirrors the certmanager approle schema): bind_secret_id: false (role_id-only login), token_bound_cidrs: [10.10.12.200/32] (agent workstation wg0 addr), deterministic role_id, 1h/4h TTLs.
  • Add policies/kv/kubernetes/agents.yaml granting the AppRole create/read/update/list on kv/data/kubernetes/* + read/list on kv/metadata/kubernetes/* (no delete).

Ordering

argocd-apps#332 (the agent-dns SA + ClusterRole + per-namespace RoleBindings) must sync before the agent-dns creds here are usable — Vault mints tokens for a service account that must already exist.

https://claude.ai/code/session_01JUoARVdmhxKQHyyyp1pxeT

## Why Agentic workloads currently need cluster-admin/root kubeconfig contexts to do routine per-domain work. This adds domain-scoped, Vault-issued kubernetes credentials plus an `agents` AppRole so agents get least-privilege access instead of escalating. ## Changes - Add `kubernetes_secret_backend_role` configs `agent-dhcp`, `agent-dns`, `agent-certs`, `agent-storage` (au/syd1): - **agent-dhcp** (Role, ns `dhcp-system`): full verbs on `kea.unkin.net` CRDs; get/list/watch pods/services/configmaps/events + pods/log. - **agent-dns** (`service_account_name` mode): mints tokens for the static `agent-dns` SA (argocd-apps#332) whose per-namespace RoleBindings confine access to bind-system/bind-internal/bind-external/externaldns. `allowed_kubernetes_namespaces: [bind-system]` (the SA's namespace). - **agent-certs** (Role, ns `cert-manager`): full verbs on `cert-manager.io` + `acme.cert-manager.io` (closes the orders/challenges debugging gap); get/list/watch/delete secrets; get/list/watch pods + pods/log. Secret delete confined to `cert-manager`. - **agent-storage** (Role, ns `cephrgw-system`): full verbs on `ceph.unkin.net` CRDs (buckets/bucketaccesses/objectstoreusers); get/list/watch pods + pods/log. - Extend the `kubernetes_secret_backend_role` module with an optional `service_account_name`; when set, `generated_role_rules`/`kubernetes_role_type` are omitted (the SA's own bindings supply RBAC). - Add creds policies for each role, bound to the `kubernetes_au_syd1_cluster_operator` ldap group (human kubectl use) and the `agents` AppRole (programmatic use). - Add the `agents` AppRole (mirrors the certmanager approle schema): `bind_secret_id: false` (role_id-only login), `token_bound_cidrs: [10.10.12.200/32]` (agent workstation wg0 addr), deterministic role_id, 1h/4h TTLs. - Add `policies/kv/kubernetes/agents.yaml` granting the AppRole create/read/update/list on `kv/data/kubernetes/*` + read/list on `kv/metadata/kubernetes/*` (no delete). ## Ordering argocd-apps#332 (the `agent-dns` SA + ClusterRole + per-namespace RoleBindings) must sync **before** the `agent-dns` creds here are usable — Vault mints tokens for a service account that must already exist. https://claude.ai/code/session_01JUoARVdmhxKQHyyyp1pxeT
unkinben added 1 commit 2026-08-02 21:29:38 +10:00
Add Vault-scoped agent kubernetes roles + agents AppRole
ci/woodpecker/pr/plan Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
41fef29bad
Give agentic workloads domain-scoped kubernetes credentials so they stop
needing cluster-admin/root. Adds four least-privilege kubernetes secret
engine roles, an `agents` AppRole (role_id-only, CIDR-bound to the agent
workstation) that can mint them, and a write-capable KV grant for the
kubernetes secrets subtree.

- Add kubernetes_secret_backend_role configs agent-dhcp/dns/certs/storage
  with generated_role_rules scoping each to its operator CRDs + pod/log reads.
- Add creds policies for each role, bound to Ben's cluster-operator ldap
  group (human kubectl use) and the agents AppRole (programmatic use).
- Add the `agents` AppRole: bind_secret_id false, token_bound_cidrs
  10.10.12.200/32, deterministic role_id, 1h/4h TTLs.
- Add kv/kubernetes/agents policy granting the AppRole create/read/update/list
  on the kubernetes KV subtree (no delete).

Claude-Session: https://claude.ai/code/session_01JUoARVdmhxKQHyyyp1pxeT
unkinben added 1 commit 2026-08-02 21:45:43 +10:00
Rework agent-dns to service_account_name mode against a static SA
ci/woodpecker/pr/plan Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
680a0455e5
Instead of generating cluster-wide RBAC, the agent-dns role now mints
tokens for a static GitOps-managed service account (argocd-apps#332)
whose per-namespace RoleBindings confine access to exactly the four bind
namespaces. Ordering: the argocd-apps RBAC must sync before these creds
are usable, since Vault mints tokens for an SA that must already exist.

- extend the kubernetes_secret_backend_role module with an optional
  service_account_name; when set, generated_role_rules and
  kubernetes_role_type are omitted (the SA's own bindings supply RBAC).
- switch the agent-dns role to service_account_name agent-dns with
  allowed_kubernetes_namespaces bind-system; drop its generated rules.

Claude-Session: https://claude.ai/code/session_01JUoARVdmhxKQHyyyp1pxeT
benvin merged commit 0e6da5cdd3 into master 2026-08-02 21:55:06 +10:00
benvin deleted branch benvin/agent-kube-contexts 2026-08-02 21:55:06 +10:00
Sign in to join this conversation.
No Reviewers
No Label
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: unkin/terraform-vault#109